libspring-orm-java - modular Java/J2EE application framework - ORM tools

Spring is a layered Java/J2EE application framework offering a lot of freedom
to Java developers yet providing well documented and easy-to-use solutions for
common practices in the industry.
This package provide spring-orm.jar : JDO support, JPA support, Hibernate
support, TopLink support, iBATIS support.


2014-11-20 - Emmanuel Bourg <>
libspring-java (3.0.6.RELEASE-17) unstable; urgency=medium
* Team upload.
* Removed the libspring-web-struts-java package and dropped
the build dependency on libstruts1.2-java
2014-10-21 - Emmanuel Bourg <>
libspring-java (3.0.6.RELEASE-16) unstable; urgency=medium
* Team upload.
* debian/rules: Fixed the JAVA_HOME variable (Closes: #766156)
* debian/control:
- Standards-Version updated to 3.9.6 (no changes)
- Build depend on libmail-java instead of glassfish-mail
- Updated the Homepage field
2014-09-15 - Emmanuel Bourg <>
libspring-java (3.0.6.RELEASE-15) unstable; urgency=medium
* Team upload.
* Transition to libasm4-java and libcglib3-java
* debian/control:
- Depend on libtomcat8-java instead of libtomcat6-java (Closes: #759635)
2014-09-06 - tony mancill <>
libspring-java (3.0.6.RELEASE-14) unstable; urgency=high
* Team upload.
* Add patch to fix CVE-2014-0225. (Closes: #753470)
- Thanks for Stephen Nelson.
2014-03-24 - Miguel Landaeta <>
libspring-java (3.0.6.RELEASE-13) unstable; urgency=high
* Fix CVE-2014-0054 and CVE-2014-1904. (Closes: #741604).
2014-01-28 - Miguel Landaeta <>
libspring-java (3.0.6.RELEASE-12) unstable; urgency=low
* Fix an FTBFS bug due to a packaging change in
libgeronimo-commonj-spec-java. (Closes: #738400).
* Update my email address in Uploaders list.
2014-01-24 - Markus Koschany <>
libspring-java (3.0.6.RELEASE-11) unstable; urgency=high
* Team upload.
* Fix CVE-2013-6429 and CVE-2013-6430. (Closes: #735420)
- New patches: CVE-2013-6429.patch and CVE-2013-6430.patch.
- Spring MVC's SourceHttpMessageConverter also processed user provided XML
and neither disabled XML external entities nor provided an option to
disable them. SourceHttpMessageConverter has been modified to provide an
option to control the processing of XML external entities and that
processing is now disabled by default.
- The JavaScriptUtils.javaScriptEscape() method did not escape all
characters that are sensitive within either a JS single quoted string, JS
double quoted string, or HTML script data context. In most cases this
will result in an unexploitable parse error but in some cases it could
result in an XSS vulnerability.
2013-12-29 - Markus Koschany <>
libspring-java (3.0.6.RELEASE-10) unstable; urgency=high
* Team upload.
* Fix CVE-2013-4152. (Closes: #720902).
- New patch: Add-processExternalEntities-to-JAXB2Marshaller.patch.
- Now by default external XML entities are not processed when unmarshalling.
Processing of external entities will only be enabled/disabled when the
source passed to the unmarshaller is a SAXSource or StreamSource. It has
no effect for DOMSource or StAXSource instances.
2013-12-03 - Markus Koschany <>
libspring-java (3.0.6.RELEASE-9) unstable; urgency=low
* Team upload.
* Update debian/build-classpath and use jackson-mapper-asl.jar and
jackson-core-asl.jar to adapt the package to the changes in
* Use compat level 9 and require debhelper >= 9.
* Bump Standards-Version to 3.9.5, no changes.
2013-09-25 - Emmanuel Bourg <>
libspring-java (3.0.6.RELEASE-8) unstable; urgency=low
* Team upload.
* Updated debian/watch to fetch the tarball from Github
* Removed the dependency on backport-util-concurrent

